<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Michel Monette — Blog &amp; writing</title><description>Articles by Michel Monette on cybersecurity, governance, applied artificial intelligence, non-profits and organisational change.</description><link>https://michelmonette.info/</link><language>en-CA</language><item><title>Why your pentest report ends up in a drawer</title><link>https://michelmonette.info/en/blog/why-your-pentest-report-ends-up-in-a-drawer/</link><guid isPermaLink="true">https://michelmonette.info/en/blog/why-your-pentest-report-ends-up-in-a-drawer/</guid><description>A penetration test report nobody reads has secured nothing. The problem is rarely technical — it is how the risk gets presented to the people who decide.</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>pentest</category><category>governance</category><category>communication</category></item><item><title>AI is already inside your company. The question is where.</title><link>https://michelmonette.info/en/blog/ai-is-already-inside-your-company/</link><guid isPermaLink="true">https://michelmonette.info/en/blog/ai-is-already-inside-your-company/</guid><description>Nobody signed a contract, yet company data is already flowing to external models. Here is how to map what exists before writing a policy nobody will follow.</description><pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate><category>AI</category><category>governance</category><category>data</category></item></channel></rss>